architecting-security

Develop structured security blueprints using defense-in-depth, zero-trust, and threat modeling.

1|Updated Apr 8, 2026
One-click install
npx skills add https://github.com/masermediagroup-stack/CursorSkills --skill architecting-security-masermediagroup-stack
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: architecting-security
Source: https://github.com/masermediagroup-stack/CursorSkills/tree/main/skills-bundle/skills/community/ai-design-components/skills/architecting-security
Command: npx skills add https://github.com/masermediagroup-stack/CursorSkills --skill architecting-security-masermediagroup-stack

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001). Use when designing security for new systems, auditing existing architectures, or establishing security governance programs.

Core Features & Use Cases

  • Defense-in-depth layering guidance across physical, network, application, data, and identity layers.
  • Zero Trust adoption patterns, continuous verification, and micro-segmentation guidance.
  • Threat modeling methodologies (STRIDE, PASTA, DREAD) with practical examples and mapping to controls.
  • Framework mappings (NIST CSF, CIS Controls, ISO 27001) and cloud architecture patterns.
  • Guidance for cloud architecture patterns (AWS, GCP, Azure) and multi-account hub designs.
  • Roadmaps and governance patterns for security programs.

Quick Start

Start by identifying greenfield vs brownfield systems, select a reference architecture (Zero Trust or Defense-in-Depth), map to applicable control frameworks, and begin a phased implementation plan.

Frequently Asked Questions about architecting-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I design a zero trust security architecture for cloud deployments?

Threat modeling methodologies like STRIDE, PASTA, and DREAD identify system vulnerabilities by categorizing risks and mapping them to security controls. They provide structured analysis to apply defense-in-depth layers and zero trust principles across application and network architectures.

Can I use this security architecture blueprint for brownfield system audits?

Yes, this security architecture blueprint applies to both greenfield designs and brownfield system audits. It evaluates existing deployments against ISO 27001, NIST CSF, and CIS Controls to produce actionable security roadmaps and governance patterns for remediation.

What is the best way to map defense-in-depth layers to compliance frameworks?

Map defense-in-depth layers to compliance frameworks by aligning physical, network, application, data, and identity security controls with NIST CSF and ISO 27001 requirements. This structured mapping creates actionable security roadmaps for governance programs and multi-cloud reference architectures.

How do I start building a phased security implementation plan using NIST CSF?

Start building a phased security implementation plan by identifying greenfield versus brownfield systems, selecting a reference architecture like Zero Trust, and mapping applicable controls to NIST CSF. This establishes a structured governance roadmap for secure system design.

Does this security architecture guidance support multi-account hub designs on AWS and Azure?

Yes, this security architecture guidance supports multi-account hub designs across AWS, GCP, and Azure. It provides cloud architecture patterns that integrate zero trust adoption and defense-in-depth layering tailored for multi-cloud reference architectures and governance programs.